Electronic certificate system
Summary by NHIP
Electronic Certificate Validation System
The system limits certificate validity checks by issuing permits with expiration dates and use limits to a second user apparatus. A certificate validity checking apparatus verifies these permit constraints before validating the electronic certificate and returning the result.
Claim Score by NHIP
Abstract
In order to limit users who can check for validity of a certificate in a system which uses public key certificates, a validity check permit permitting a request to check for validity of the certificate is issued by a permit issuing server 120 to the applicant of the certificate. The certificate applicant sends the validity check permit to a relevant user when the certificate is used (step 701). When having a certificate validity checking server check for validity of the certificate, the user sends the validity check permit of the certificate to be checked to the certificate validity checking server (step 704). The certificate validity checking server verifies the validity check permit (step 706).

Term
Term ended
Expired 2 August 2024, 2.1 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
37 claims: 4 independent, 33 dependent
- 1Broadest claimClaim Score 46, average(NHIP)An electronic certificate system that uses an electronic certificate, comprising:a first user apparatus used by an issuee of the electronic certificate;a second user apparatus, connected with the first user apparatus over a network, that receives required data and the electronic certificate that are sent from the first user apparatus;and a certificate validity checking apparatus, connected with the network, that receives request information indicating a request to check for validity of the electronic certificate and validity check permission information indicating that checking for validity of the electronic certificate is permitted, which are sent from the second user apparatus;detects an expiration date of a validity check permit and an upper limit on a number of uses of the validity check permit based on the received validity check permission information;checks whether the expiration date has not passed and whether an accounted number of uses of the validity check permission is smaller than the upper limit;if the expiration date has not passed and the accounted number is smaller than the upper limit, checks for validity of the electronic certificate;and sends the result of the check processing to the second user apparatus.
- 12A validity checking apparatus for an electronic certificate connected over a network with a first user apparatus used by an issuee of the electronic certificate, and a second user apparatus that is connected with the first user apparatus over the network and receives required data and the electronic certificate from the first user apparatus, the validity checking apparatus comprising:a network connection part connected with the network;and a control unit, connected with the network connection part and a storage unit in which a program is stored, that receives request information indicating a request to check for validity of the electronic certificate and validity check permission information indicating that checking for validity of the electronic certificate is permitted, from the second user apparatus according to the program, detects an expiration date of a validity check permit and an upper limit on a number of uses of the validity check permit based on the received validity check permission information, checks whether the expiration date has not passed and whether an accounted number of uses of the validity check permission is smaller than the upper limit and if the expiration date has not passed and the accounted number is smaller than the upper limit, checks for validity of the electronic certificate, wherein the network connection part sends the result of the check processing to the second user apparatus.
- 23A program storable in a medium readable by a computer connected over a network with a first user apparatus used by an issuee of an electronic certificate, and a second user apparatus that is connected with the first user apparatus over the network and receives required data and the electronic certificate from the first user apparatus, the program including the following steps executed by the computer:receiving request information indicating a request to check for validity of the electronic certificate and validity check permission information indicating that checking for validity of the electronic certificate is permitted from the second user apparatus;detecting an expiration date of a validity check permit and an upper limit on a number of uses of the validity check permit based on the received validity check permission information;checking whether the expiration date has not passed and whether an accounted for number of uses of the validity check permission is smaller than the upper limit;if the expiration date has not passed and the accounted number is smaller than the upper limit, checking for validity of the electronic certificate;and sending the result of the check processing to the second user apparatus.
- 34A certificate validity checking method that uses a system in which plural terminals and a server apparatus are connected with each other over a network, and for requesting to check for validity of an electronic certificate delivered from a terminal included in the plural terminals, and that allows the server apparatus to check for validity of the certificate, the method including the steps of:sending validity check permission information indicating that a first terminal included in the plural terminals permits checking for validity of the certificate in the server apparatus, and the certificate to a second terminal included in the plural terminals;the second terminal receiving the validity check permission information and the certificate and sending the validity check permission information and a request to check for validity of the certificate to the server apparatus;and the server apparatus receiving the validity check permission information sent from the second terminal, detecting an expiration date of validity check permit and an upper limit on a number of uses of the validity check permit based on the received validity check permission information, checking whether the expiration date has not passed and whether an accounted number of uses of the validity check permission is smaller than the upper limit and if the expiration date has not passed and the accounted number is smaller than the upper limit, checking for validity of the certificate.
Independent claims4
142 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
0001The present invention relates to a system which uses a network for providing services. The present invention also includes apparatuses and program products constituting the system. The present invention relates in particular to a certificate validity checking method and apparatus, especially for use in a system using certificates based on a public key.
0002A method of providing services in a system using a network is disclosed in Japanese Published Unexamined Patent Application No. 2000-123095. In this publication, a technique is disclosed which defines many different types of electronic tickets for general purpose use to provide services.
0003A recent major trend in electronic commerce and communications is toward authentication processing using public-key-based certificates (hereinafter referred to as public key certificates or simply as certificates), and communication encryption processing.
0004On an electronic certificate, there are provided an issuance date, an expiration date, the signature of an issuer, and the like, in addition to information co concerning the certifyee of the certificate. During the effective period, there should be no problem in the validity of the certificate itself.
0005However, it might become necessary to nullify the certificate during the effective period because of loss or theft of the secret key corresponding to the certificate, or due to company retirement. This is called certificate nullification processing. An authentication station periodically (e.g., twice per day) prepares and stores a nullification list containing a list of serial numbers of certificates that became null during the effective period. The nullification list is called a CRL (Certificate Revocation List) according to RFC (Request for Comments) 2459 of the IETF (Internet Engineering Task Force).
0006In applications (Web server, client, encrypted mail) using certificates, the validity of the certificate can not be confirmed without information about whether the certificate has been nullified. As a method of checking a certificate for validity (certificate validity checking method), a method has been employed by which users obtain a CRL by some method (periodic distribution by an authentication station to users or access to the authentication station by users), and confirm the validity of the certificate by confirming that there is no certificate information to be checked for validity in the CRL.
0007In applications using a CRL distributed from an authentication station, the CRL data must be analyzed to determine whether a certificate is nullified.
0008OCSP (Online Certificates Status Protocol) recommended as RFC 2560 of IETF lessens loads on the applications and defines a protocol for inquiring of an OCSP responder as to whether a certificate itself is valid.
0009The responder obtains and manages a nullification list issued from an authentication station, whereby the applications can manipulate a validity checking protocol called OCSP to check for the validity without the applications themselves searching the nullification list.
SUMMARY OF THE INVENTION
0010The above-described methods and procedures do not include a solution to the following points.
0011In Japanese Published Unexamined Patent Application No. 2000-123095, services provided from a server apparatus cannot be provided to third parties (third client apparatuses). Also, there is a problem in that the number of provisions, the time, and other factors cannot be limited.
0012Since there are no limitations on a request to check for the validity of a certificate for a server checking for the validity of a certificate, such as an OCSP responder, an indefinite number of users issue a certificate validity check request to the server, with the result that the server is highly loaded. It is readily expected that widespread use of a public key certificate will result in the frequent occurrence of certificate validity checking. Also, it is expected that the concentration of a large number of validity check request accesses to the server will cause an increase in the load on the server.
0013To solve the above-described problems, the present invention has the following configuration.
0014A service requesting apparatus used by a user requesting services, a service receiving apparatus used by a user receiving services, and a service providing apparatus performing information processing for providing services are connected with each other over a network, wherein the service providing apparatus receives a service request sent from the service receiving apparatus and determines whether to perform information processing for providing the service, based on a condition related to the service request, for performing information processing for the service receiving apparatus, the information processing being ascribable to processing of the service requesting apparatus.
0015According to the present invention, the above-described condition also includes the existence of permission information that allows provision or receipt of a service sent from the service requesting apparatus to the service receiving apparatus. The permission information may be created by either the service providing apparatus or the service requesting apparatus. Also, it may be created by a third apparatus.
0016The above-described condition includes the inclusion of the service receiving apparatus in an information processing apparatus registered in advance. In this case, information about the information processing apparatus is registered in the service providing apparatus. It may also be registered in an apparatus accessible from the service providing apparatus.
0017When a service request is received, the service providing apparatus sends out inquiry information about whether to provide the service to the service requesting apparatus. In this case, the above-described condition includes a reply to the inquiry. Also, information for identifying the service receiving apparatus is sent from the service providing apparatus to the service requesting apparatus.
0018The above-described condition includes information indicating limitations on a service to be provided. The limitations include at least one of a number of service provisions and a provision date.
0019Services include checking for validity of an electronic certificate. In this case, the service requesting apparatus is an information processing apparatus managed by an issuee of the certificate. The service receiving apparatus is an information processing apparatus that receives the certificate from the service requesting apparatus. Further, the service providing apparatus is a certificate validity checking server. The service providing apparatus may include an information processing apparatus that issues the certificate. Other services include distribution of information including programs, music, and images, and delivery of products including presents.
BRIEF DESCRIPTION OF THE DRAWINGS
0020<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of a system according to a first embodiment of the present invention.
0021<figref idref="DRAWINGS">FIG. 2</figref> is a diagram showing the data structure of a validity check permit in the first embodiment.
0022<figref idref="DRAWINGS">FIG. 3</figref> is a diagram showing the data structure of an issued validity check permit table in the first embodiment.
0023<figref idref="DRAWINGS">FIG. 4</figref> is a diagram showing the data structure of a validity permit inspection table in the first embodiment.
0024<figref idref="DRAWINGS">FIG. 5</figref> is a flowchart showing a certificate issuing procedure in a processing procedure in the first embodiment.
0025<figref idref="DRAWINGS">FIG. 6</figref> is a flowchart showing a procedure for issuing a validity check permit in the processing procedure in the first embodiment.
0026<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart showing a procedure for checking for validity of a certificate in the processing procedure in the first embodiment.
0027<figref idref="DRAWINGS">FIG. 8</figref> is a detailed flowchart of validity check permit inspection processing in the processing in <figref idref="DRAWINGS">FIG. 7</figref>.
0028<figref idref="DRAWINGS">FIG. 9</figref> is a block diagram showing the configuration of a permission registration server according to a second embodiment.
0029<figref idref="DRAWINGS">FIG. 10</figref> is a diagram showing the data structure of a validity check permission registration table in the second embodiment.
0030<figref idref="DRAWINGS">FIG. 11</figref> is a flowchart showing a permission registration procedure of validity confirmation in a processing procedure in the second embodiment.
0031<figref idref="DRAWINGS">FIG. 12</figref> is a flowchart showing a procedure for checking for validity of a certificate in the processing procedure in the second embodiment.
0032<figref idref="DRAWINGS">FIG. 13</figref> is a detailed flowchart of registration content check processing of validity check permission registration in the processing in <figref idref="DRAWINGS">FIG. 12</figref>.
0033<figref idref="DRAWINGS">FIG. 14</figref> is a flowchart showing a processing procedure according to a third embodiment of the present invention.
0034<figref idref="DRAWINGS">FIG. 15</figref> is a diagram showing the data structure of an accounting information table according to an embodiment of the present invention.
DESCRIPTION OF THE PREFERRED EMBODIMENTS
First Embodiment
0035Hereinafter, a first embodiment of the present invention will be described.
0036<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram showing the configuration of a certificate validity checking system when the present invention is applied to a validity check service for a public key certificate.
0037In this specification, for a given user's public key, a server issuing a certificate of the key will be referred to as a certificate issuing server. For an inquiry about certificate validity from a terminal, a server that checks whether a certificate specified by the terminal is valid and that returns the result of the processing will be referred to as a certificate validity checking server. Information giving permission for a request to execute certificate validity check processing to the certificate validity checking server will be referred to as a validity check permit. A server that creates a validity check permit and sends it to the terminal will be referred to as a permit issuing server. A server that issues a validity check permit and holds information (accounting information) about charges imposed on users according to validity check processing will be referred to as a settlement server.
0038In <figref idref="DRAWINGS">FIG. 1</figref>, the system comprises a certificate issuing server <b>110</b>, a permit issuing server <b>120</b>, a certificate validity checking server <b>130</b>, a settlement server <b>190</b>, and terminals <b>140</b>, <b>150</b> and <b>160</b> respectively used by user A, user B, and user C, who use a certificate validity check service.
0039The certificate issuing server <b>110</b>, the permit issuing server <b>120</b>, the certificate validity checking server <b>130</b>, the settlement server <b>190</b>, and the terminals <b>9</b> are respectively controlled by control units <b>112</b>, <b>122</b>, <b>132</b>, <b>192</b>, <b>142</b>, and <b>152</b>, and they respectively have network connection parts <b>111</b>, <b>121</b>, <b>131</b>, <b>191</b>, <b>141</b>, and <b>151</b> for mutual data sending and receiving among them through connection with a network <b>170</b>, such as the Internet, via a communication line.
0040Although three terminals are shown in <figref idref="DRAWINGS">FIG. 1</figref>, the present invention is not limited to three. Although the servers are respectively shown as only one each, there may exist plural servers having an identical function. Although the servers are separately shown, they may be embodied in a physically identical server.
0041The certificate issuing server <b>110</b> has a program having a certificate creating function <b>115</b>, a certificate sending function <b>116</b> and a signature function <b>117</b> within a storage unit <b>113</b>.
0042The permit issuing server <b>120</b> has a program <b>124</b>, having a validity check permit creating function <b>125</b>, a validity check permit sending function <b>126</b>, and a signature and signature verification function <b>127</b>, as well as an issued validity check permit table <b>300</b> within a storage unit <b>123</b>.
0043The certificate validity checking server <b>130</b> has a program, having a validity check permit receiving function <b>135</b>, a validity check permit inspection function <b>136</b>, a certificate validity checking function <b>137</b>, and a signature and signature verification function <b>138</b>, as well as a validity check permit inspection table <b>400</b> within a storage unit <b>133</b>.
0044The settlement server <b>190</b> has a program <b>194</b>, having an accounting information receiving function <b>195</b>, and an accounting information table <b>1500</b> within a storage unit <b>193</b>.
0045The terminals <b>140</b> and <b>150</b> respectively have programs <b>144</b> and <b>154</b> respectively having certificate sending/receiving functions <b>145</b> and <b>155</b>, validity check permit sending/receiving functions <b>146</b> and <b>156</b>, and signature and signature verification functions <b>147</b> and <b>157</b> within storage units <b>143</b> and <b>153</b>.
0046<figref idref="DRAWINGS">FIG. 2</figref> is a diagram showing the data structure of a validity check permit.
0047The validity check permit <b>200</b> includes: identification information <b>201</b> of a permit issuing server; identification information <b>202</b> of a validity check permit; identification information <b>203</b> of a certificate issuing server; certificate identification information <b>204</b>; identification information <b>205</b> of a certificate validity checking server; an expiration date of validity check permit <b>206</b>; an upper limit <b>207</b> on the number of uses of a validity check permit; and an electronic signature <b>208</b> of a permit issuing server as information for verifying whether the validity check permit has been tampered with after being created.
0048If the validity check permit is valid, the certificate validity checking server checks for the validity of a public key certificate identified by the identification information <b>203</b> of the certificate issuing server and the certificate identification information <b>204</b> included in the validity check permit.
0049<figref idref="DRAWINGS">FIG. 3</figref> is a diagram showing the data structure of the issued validity check permit table <b>300</b>. The issued validity check permit table <b>300</b> consists of: identification information <b>301</b> of a validity check permit; identification information <b>302</b> of a certificate issuing server; certificate identification information <b>303</b>; identification information <b>304</b> of certificate validity checking server; an expiration date <b>305</b> of validity check permit; and an upper limit <b>306</b> on the number of uses of validity check permit.
0050<figref idref="DRAWINGS">FIG. 4</figref> is a diagram showing the data structure of the validity check permit inspection table <b>400</b>.
0051The validity check permit inspection table <b>400</b> consists of: identification information <b>401</b> of a permit issuing server; identification information <b>402</b> of a validity check permit; an upper limit <b>403</b> on the number of uses of a validity check permit; and an accumulated number <b>404</b> of uses of a validity check permit.
0052<figref idref="DRAWINGS">FIG. 15</figref> is a diagram showing the data structure of the accounting information table <b>1500</b>.
0053Although, in this embodiment, functions and tables of servers and terminals exist within identical storage units and within identical programs, the functions may exist in different programs or different storage units.
0054<figref idref="DRAWINGS">FIGS. 5</figref>, <b>6</b>, and <b>7</b> are flowcharts showing a processing procedure of this embodiment. The operation of each part will be described based on the flowcharts. The certificate issuing server <b>110</b>, for a certificate issuance request from a user A, creates the certificate using the certificate creating function <b>115</b> (step <b>501</b>) and affixes an electronic signature of the certificate issuing server to the certificate as information for detecting a tampering with the certificate.
0055The certificate issuing server <b>110</b> sends the certificate to terminal <b>140</b> of the user A using the certificate sending function <b>116</b> via a network (step <b>502</b>).
0056The terminal <b>140</b>, using the certificate receiving function <b>145</b>, receives and stores the certificate sent from the certificate issuing server <b>110</b> (step <b>503</b>).
0057The terminal <b>140</b> sends a request to issue a validity check permit to the permit issuing server <b>120</b> (step <b>601</b>). The issuance request includes identification information of the permit issuing server, identification information of the certificate of the user A, an upper limit on the number of uses of a validity check permit, and an expiration date of the validity check permit, and is provided with an electronic signature of the user A.
0058The permit issuing server <b>120</b> receives the issuance request (step <b>602</b>), verifies the electronic signature using the signature and signature verification function <b>127</b>, and confirms that the issuance request has been created by the user A and has not been tampered with (step <b>603</b>). A method of verifying an electronic signature can be performed using the public key cryptosystem.
0059If verification of the electronic signature fails, the permit issuing server <b>120</b> sends information indicating that the issuance request is invalid to the terminal <b>140</b> (step <b>608</b>), and the terminal <b>140</b> receives the result (step <b>609</b>).
0060If verification of the electronic signature fails, the permit issuing server <b>120</b> creates a validity check permit <b>200</b> using the validity check permit creating function <b>125</b> and affixes an electronic signature of the permit issuing server to the validity check permit, as information for detecting tampering (step <b>604</b>).
0061Identification information of the certificate issuing server and the certificate identification information <b>204</b> included in the validity check permit <b>200</b> are information included in the issuance request and identify the server <b>110</b> that issued the certificate of the user A and the certificate of the user A, respectively.
0062The permit issuing server <b>120</b> adds the data of the created validity check permit <b>200</b> to the issued validity check permit table <b>300</b> (step <b>605</b>).
0063The permit issuing server <b>120</b> sends the validity check permit <b>200</b> to the terminal <b>140</b> of the user A using the validity check permit sending/receiving function <b>126</b> via the network (step <b>606</b>).
0064The permit issuing server <b>120</b> sends accounting information (payer's identification information, receiver's identification information, charged amounts, and occurrence reason) to the settlement server <b>190</b> (step <b>610</b>).
0065The terminal <b>140</b>, using the validity check permit sending/receiving function <b>146</b>, receives the validity check permit sent from the permit issuing server <b>120</b> (step <b>607</b>).
0066The settlement server <b>190</b>, using the accounting information receiving function <b>195</b>, receives the accounting information sent from the permit issuing server <b>120</b> and adds the received accounting information to the accounting information table <b>1500</b> after adding an occurrence date (step <b>611</b>).
0067When the certificate is used, for example, to send an electronic document, provided with the electronic signature of the user A, to the terminal <b>150</b> of the user B, who is to be told that the certificate of the user A is valid, the terminal <b>140</b> sends the validity check permit <b>200</b> using the validity check permit sending/receiving functions <b>146</b> via the network (step <b>701</b>).
0068The terminal <b>150</b>, using the validity check permit sending/receiving function <b>156</b>, receives the validity check permit <b>200</b> sent from the terminal <b>140</b> (step <b>702</b>).
0069The terminal <b>150</b> fetches identification information <b>205</b> of certificate validity checking server from the validity check permit <b>200</b> (step <b>703</b>), and it sends a certificate validity check request and the validity check permit <b>200</b>, using the validity check permit sending/receiving function <b>156</b>, to a validity checking server <b>130</b> by the fetched identification information (step <b>704</b>).
0070The certificate validity checking server <b>130</b>, using the validity check permit receiving function <b>135</b>, receives the validity check permit <b>200</b> sent from the terminal <b>150</b> (step <b>705</b>).
0071The certificate validity checking server <b>130</b>, using the validity check permit inspection function <b>136</b>, checks whether the received validity check permit <b>200</b> is valid (step <b>706</b>). After inspection of all items or after a proper type of inspection is conducted, if it is determined that all items are correct, the certificate validity checking server <b>130</b>, for the certificate validity check request, checks for the validity of the certificate. However, if it is determined by the inspection that the validity check permit <b>200</b> is incorrect and invalid, the certificate validity checking server <b>130</b> does not check for the validity of the certificate and to the terminal <b>150</b> a result indicating that the certificate validity checking processing cannot be performed (step <b>710</b>), and the terminal <b>150</b> receives this result (step <b>711</b>).
0072The certificate validity checking server <b>130</b> sends accounting information (payer's identification information, receiver's identification information, charged amounts, and occurrence reason) to the settlement server <b>190</b> (step <b>712</b>). The settlement server <b>190</b>, using the accounting information receiving function <b>195</b>, receives the accounting information sent from the certificate validity checking server <b>130</b> and adds the received accounting information to the accounting information table <b>1500</b> after adding an occurrence date (step <b>713</b>).
0073<figref idref="DRAWINGS">FIG. 8</figref> is a flowchart showing in detail the processing (step <b>706</b>) that checks for validity of a validity check permit. The operation of each part will be described based on the flowchart.
0074In the processing that checks for validity of a validity check permit, an electronic signature of the validity check permit <b>200</b> is verified (step <b>801</b>), and it is determined whether the validity check permit <b>200</b> is created by the permit issuing server <b>120</b> and has not been tampered with after being created (step <b>802</b>). If it has not been tampered with, the certificate validity checking server <b>130</b> reads an expiration date of validity check permit <b>206</b> included in the validity check permit <b>200</b> to check whether the expiration date has passed (step <b>803</b>). If the expiration date has not passed, the certificate validity checking server <b>130</b> fetches identification information <b>201</b> of the permit issuing server and identification information <b>202</b> of the validity check permit from the validity check permit <b>200</b> (step <b>804</b>), and searches the validity check permit inspection table <b>400</b> for the fetched identification information (step <b>805</b>).
0075If no pertinent data exists in the validity check permit inspection table <b>400</b>, data is newly added to the validity check permit inspection table <b>400</b> from information contained in the permit <b>200</b> (step <b>806</b>).
0076An upper limit <b>403</b> on the number of uses and an accumulated number of uses <b>404</b> of the validity check permit are obtained from the validity check permit inspection table <b>400</b> (step <b>807</b>). If the accumulated number of uses <b>404</b> is smaller than the upper limit <b>403</b> on the number of uses, the certificate validity checking server <b>130</b> adds “1” to the accumulated number of uses <b>404</b> of the validity check permit inspection table <b>400</b> (step <b>809</b>).
0077The certificate validity checking server <b>130</b> fetches identification information <b>203</b> of the certificate issuing server and certificate identification information <b>204</b> from the validity check permit <b>200</b> (step <b>707</b>) and checks for the validity of a certificate identified by the fetched identification information (step <b>708</b>).
0078Certificate validity checking processing can be achieved using the public key cryptosystem. For example, one method is to obtain and refer to a CRL issued by a certificate issuing server to check whether the CRL is provided with a certificate indicating validity.
0079The certificate validity checking server <b>130</b> sends the result of validity checking processing to the terminal <b>150</b> after affixing an electronic signature to it (step <b>709</b>), and the terminal <b>150</b> receives the result (step <b>711</b>).
0080Although, in the above-described first embodiment, the use of a validity check permit is limited by the combination of an expiration date and an upper limit on the number of uses of a validity check permit, limitation methods are not limited to this. For example, the use of a validity check permit may be limited simply by an expiration date or merely by an upper limit on the number of uses, or it may be permitted only for a given period after the first use of the validity check permit.
0081Although, in the first embodiment, the validity check permit <b>200</b> holds certificate identification information <b>204</b> and use limitation information (expiration date <b>206</b> and an upper limit <b>207</b> on the number of uses) of the validity check permit, these items of information may be managed in the permit issuing server <b>120</b>. In this case, the validity check permit <b>200</b> holds identification information <b>201</b> of the permit issuing server and identification information <b>202</b> of the validity check permit, and a certificate validity checking server <b>130</b> receiving the validity check permit <b>200</b> inquires of a permit issuing server identified by the identification information of the permit issuing server about certificate identification information and use limitation information of the validity check permit.
0082Although, in the first embodiment, the validity check permit <b>200</b> is created by the permit issuing server <b>120</b>, the user A may create it. In this case, identification information <b>201</b> of permit issuing server of the validity check permit <b>200</b> is not required, and an electronic signature of the user A is affixed instead of an electronic signature <b>208</b> of the permit issuing server.
0083Although, in the above-described embodiment, the terminal <b>150</b> of the user B sends the validity check permit <b>200</b> to a certificate validity checking server <b>130</b> identified by identification information <b>205</b> of the certificate validity checking server included in the validity check permit <b>200</b> to request that a check be made to see if the certificate is valid, the validity check permit <b>200</b> may be sent to other equipment so that the equipment receiving it, in place of the terminal <b>150</b> will send the validity check permit <b>200</b> to the certificate validity checking server <b>130</b> to request that a check is made to see if the certificate is valid and return the check result to the terminal <b>150</b>.
0084Although, in the above-described embodiment, accounting information is sent to the settlement server in both of the processing steps (steps <b>610</b> and <b>712</b>) of permit issuance and certificate validity checking, accounting information may be sent in only one of these processing steps.
Second Embodiment
0085A second embodiment will be described based on the configuration of the first embodiment.
0086The following points are different between the system configuration in the first embodiment of <figref idref="DRAWINGS">FIG. 1</figref> and a system configuration in the second embodiment.
0000(a) The permit issuing server <b>120</b> is not required.
0000(b) The validity check permit sending/receiving functions <b>146</b> and <b>156</b> of each terminal, the validity check permit receiving function <b>136</b> and validity check permit inspection function <b>137</b> of the certificate validity checking server <b>130</b> are not required.
0000(c) A permission registration server <b>180</b> shown in <figref idref="DRAWINGS">FIG. 9</figref> has a network connection part <b>181</b> which is connected to the network <b>170</b>.
0087The permission registration server <b>180</b> is an apparatus that allow users to have the certificate validity checking server <b>130</b> perform certificate validity checking processing. It is controlled by a control unit <b>182</b> and has a program <b>184</b>, having a signature verification function <b>185</b>, and a validity check permission registration table <b>1000</b> within a storage unit <b>183</b>.
0088<figref idref="DRAWINGS">FIG. 10</figref> is a diagram showing the data structure of the validity check permission registration table <b>1000</b>. The validity check permission registration table <b>1000</b> consists of identification information <b>1001</b> of a permittee, identification information <b>1002</b> of a certificate issuing server, certificate identification information <b>1003</b>, registration expiration date <b>1004</b>, an upper limit <b>1005</b> on the number of uses, and an accumulated number <b>1006</b> of uses.
0089In this embodiment, although only one of each of the servers is shown, there may exist plural servers having an identical function. Although the servers are respectively different, they may be an identical server.
0090<figref idref="DRAWINGS">FIGS. 11 and 12</figref> are flowcharts showing a processing procedure used in this embodiment. The operation of each part will be described based on the flowcharts.
0091The step of issuing a certificate (step <b>501</b>) to the step of the terminal <b>140</b> storing the certificate (step <b>503</b>) are the same as those in the first embodiment.
0092The terminal <b>140</b> sends a registration request to the permission registration server <b>180</b> (step <b>1101</b>). The registration request includes identification information of a certificate issuing server that issued a certificate of user A, identification information of the certificate of user A, identification information of user B subject to permission registration, and permission limitation information, such as a deadline for permission of the validity check request and an upper limit on the number of validity check requests, and the registration request is provided with an electronic signature of user A.
0093The permission registration server <b>180</b> receives the registration request (step <b>1102</b>) and checks whether the registration request is valid (step <b>1103</b>). The check consists of a check about whether the electronic signature of user A is correct and a check about whether information contained in the registration request conforms to a predetermined format.
0094If the check indicates that the registration request is not valid, the permission registration server <b>180</b> sends this fact to the terminal <b>140</b> (step <b>1106</b>), which receives the result (step <b>1107</b>).
0095If the check indicates that the registration request is valid, the permission registration server <b>180</b> adds the identification information of the certificate issuing server, certificate identification information, identification information of the permittee (user B), the registration expiration date, an upper limit on the number of permitted uses, and an accumulated number of uses of “0” to the validity check permission registration table <b>1000</b> (step <b>1104</b>), and sends a registration completion event to the terminal <b>140</b> (step <b>1105</b>), which receives the result (step <b>1107</b>).
0096The permission registration server <b>180</b> sends accounting information (payer's identification information, receiver's identification information, charged amounts, and occurrence reason) to the settlement server <b>190</b> (step <b>1108</b>). The settlement server <b>190</b>, using the accounting information receiving function <b>195</b>, receives the accounting information sent from the permission registration server <b>180</b> and adds the received accounting information to the accounting information table <b>1500</b> after adding an occurrence date (step <b>1109</b>).
0097The terminal <b>150</b> of the user B, who intends to check for validity of the certificate of the user A, sends a validity check request to the certificate validity checking server <b>130</b> (step <b>1201</b>). The validity check request includes identification information of user B, identification information of a certificate issuing server that issued the certificate of the user A, identification information of the certificate of the user A, and identification information of a permission registration server in which the user B is permitted to check for validity, and is provided with an electronic signature of the user B.
0098The certificate validity checking server <b>130</b> receives the validity check request (step <b>1202</b>) and verifies the electronic signature to authenticate the user B (step <b>1203</b>).
0099If the authentication is unsuccessful, the certificate validity checking server <b>130</b> informs the terminal <b>150</b> that validity checking processing cannot be performed (step <b>1204</b>), and the terminal <b>150</b> receives this result (step <b>1214</b>).
0100If the authentication is successful, the certificate validity checking server <b>130</b> reads identification information of permission registration server from the validity check request (step <b>1205</b>), and, in order to determine whether the user B is permitted to check for validity of the certificate of the user A, it sends a permission registration check request to the permission registration server <b>180</b> (step <b>1206</b>). The permission registration check request includes identification information of the user B, identification information of a server that issued the certificate of the user A, and identification information of the certificate of the user A.
0101The permission registration server receives the permission registration check request (step <b>1207</b>), searches the validity check permission registration table for the request, checks the registration contents (step <b>1208</b>), and sends a check result to the certificate validity checking server <b>130</b> (step <b>1209</b>).
0102<figref idref="DRAWINGS">FIG. 13</figref> is a flowchart showing details of the permission registration content checking processing (step <b>1208</b>). The processing procedure of step <b>1208</b> will be described based on the flowchart. To check the registration contents of the validity check permission registration table <b>1000</b>, identification information of a server that issued the certificate of the user A, identification information of the certificate of the user A, and identification information of the user B are respectively used to search the items of identification information <b>1002</b> of the certificate issuing server, certificate identification information <b>1003</b>, and identification information <b>1001</b> of the permittee of the validity check permission registration table <b>1000</b> (step <b>1301</b>).
0103If no pertinent data exists in the validity check permission registration table <b>1000</b>, the result of checking is “no permission” (step <b>1308</b>).
0104If pertinent data exists in the validity check permission registration table <b>1000</b>, the registration expiration date <b>1004</b>, an upper limit <b>1005</b> on the number of uses, and an accumulated number <b>1006</b> of uses are obtained from the data (step <b>1303</b>).
0105Next, it is checked whether the registration expiration date <b>1004</b> has passed (step <b>1304</b>). If the registration expiration date <b>1004</b> has passed, the result of registration content checking is “no permission” (step <b>1308</b>).
0106If the registration expiration date <b>1004</b> has not passed, it is checked whether the accumulated number <b>1006</b> of uses is smaller than the upper limit <b>1005</b> on the number of uses (step <b>1305</b>). If the accumulated number <b>1006</b> of uses is equal to or greater than the upper limit <b>1005</b> on the number of uses, the result of registration content checking is “no permission” (step <b>1308</b>). If it is smaller than the upper limit <b>1005</b> on the number of uses, “1” is added to the accumulated number of uses of the validity check permission registration table <b>1000</b> (step <b>1306</b>), and the result of registration content checking is “permission” (step <b>1307</b>).
0107The certificate validity checking server <b>130</b> receives the check result for the permission registration check request from the permission registration server <b>180</b> (step <b>1210</b>).
0108The check result is read (step <b>1211</b>). If the check result is “no permission”, the certificate validity checking server <b>130</b> informs the terminal <b>150</b> that validity check processing cannot be performed (step <b>1204</b>), and the terminal <b>150</b> receives this result (step <b>1214</b>).
0109If the check result is “permission”, the certificate validity checking server <b>130</b> checks whether a certificate, identified by identification information <b>203</b> of the certificate issuing server and certificate identification information <b>204</b> included in the validity check request, is valid (step <b>1212</b>), and sends the result of the validity check processing to the terminal <b>150</b> after affixing an electronic signature to the result (step <b>1213</b>), and the terminal <b>150</b> receives the result (step <b>1215</b>).
0110The certificate validity checking server <b>130</b> sends accounting information (payer's identification information, receiver's identification information, charged amounts, and occurrence reason) to the settlement server <b>190</b> (step <b>1215</b>). The settlement server <b>190</b>, using the accounting information receiving function <b>195</b>, receives the accounting information sent from the certificate validity checking server <b>130</b>, and adds the received accounting information to the accounting information table <b>1500</b> after adding an occurrence date (step <b>1216</b>).
0111Although, like the variation of the first embodiment, the use of a validity check permit is limited by combination of an expiration date and an upper limit on the number of uses of a validity check permit, limitation methods are not limited to this.
0112Although, in the above-described embodiment, accounting information is sent to the settlement server in both of the processing steps (steps <b>610</b> and <b>712</b>) of permission registration and certificate validity checking, accounting information may be sent in only one of the processing steps.
Third Embodiment
0113A third embodiment will be described based on the configuration of the first embodiment.
0114The following points are different between the system configuration in the first embodiment of <figref idref="DRAWINGS">FIG. 1</figref> and the system configuration in the third embodiment.
0000(a) The permit issuing server <b>120</b> is not required.
0000(b) The validity check permit sending/receiving functions <b>146</b> and <b>156</b> of each terminal, the validity check permit receiving function <b>136</b> and validity check permit inspection function <b>137</b> of the certificate validity checking server <b>130</b> are not required.
0115<figref idref="DRAWINGS">FIG. 14</figref> is a flowchart showing the processing procedure used in this embodiment. The operation of each part will be described based on the flowcharts.
0116The step of issuing a certificate (step <b>501</b>) to the step of the terminal <b>140</b> storing the certificate (step <b>503</b>) are the same as those in the first embodiment.
0117The terminal <b>150</b> of the user B, who intends to check for validity of the certificate of the user A, sends a validity check request to the certificate validity checking server <b>130</b> (step <b>1401</b>). The validity check request includes identification information of a certificate issuing server that issued the certificate of the user A, and identification information of the certificate of the user A, and the validity check request is provided with an electronic signature of the user B.
0118The certificate validity checking server <b>130</b> receives the validity check request (step <b>1402</b>) and verifies the electronic signature to authenticate the user B (step <b>1403</b>).
0119If the authentication is unsuccessful, the certificate validity checking server <b>130</b> informs the terminal <b>150</b> that validity checking processing cannot be performed (step <b>1404</b>), and the terminal <b>150</b> receives this result (step <b>1212</b>).
0120If the authentication is successful, the certificate validity checking server <b>130</b> sends a permission request to the terminal <b>140</b> of the user A (step <b>1405</b>). The permission request includes identification information of the user B.
0121The terminal <b>140</b> receives the permission request (step <b>1406</b>), and sends, to the certificate validity checking server <b>130</b>, the result of “permission” or “no permission” to indicate whether the user B identified by identification information included in the permission request is permitted to check for validity of the certificate (step <b>1407</b>).
0122The certificate validity checking server <b>130</b> receives the result from the terminal <b>140</b> (step <b>1408</b>) and checks the result (step <b>1409</b>).
0123If the result of the permission request is “no permission”, the certificate validity checking server <b>130</b> informs the terminal <b>150</b> that validity check processing cannot be performed, as a result of the certificate validity check request (step <b>1404</b>), and the terminal <b>150</b> receives the result (step <b>1212</b>).
0124If the result of the permission request is “permission”, the certificate validity checking server <b>130</b> checks whether a certificate identified by identification information of a certificate issuing server and certificate identification information included in the validity check request is valid (step <b>1410</b>), and sends a validity check result to the terminal <b>150</b> (step <b>1411</b>), and the terminal <b>150</b> receives the certificate validity check result.
0125The certificate validity checking server <b>130</b> sends accounting information (payer's identification information, receiver's identification information, charged amounts, and occurrence reason) to the settlement server <b>190</b> (step <b>1413</b>). The settlement server <b>190</b>, using the accounting information receiving function <b>195</b>, receives the accounting information sent from the certificate validity checking server <b>130</b>, and adds the received accounting information to the accounting information table <b>1500</b> after adding an occurrence date (step <b>1414</b>).
0126Embodiments in which the present invention is applied to methods of checking for validity of public key certificates have been described above. The following effects, for example, are obtained by these methods.
0127Since charges paid by certificate users are fixed utilization charges, such as the amount of issuance of certificate, monthly amounts, and yearly amounts, the charges have been high to users using certificates less frequently.
0128Where users are charged according to the number of certificate validity check processings, persons who access a validity check request, and the certifyees of certificates may be included in candidates for being charged.
0129Although persons who access a validity check request can be identified by affixing an electronic signature of the accessing persons to the validity check request using an optional function of OSCP, in some cases, it may be difficult to identify accessing persons because they do not have a certificate, or for other reasons. The certifyees of certificates can be easily identified by consulting an authentication station that issued the certificates.
0130If no limitation is placed on validity check processing, the validity check processing may be performed also for requests from users who are not assumed to check for validity of a certificate, or requests in an unexpected situation.
0131According to the present invention, by limiting execution of certificate validity check processing according to the will of the certifyees of certificates, validity check processing unnecessary for the certifyees of certificates can be prevented, and the certifyees of certificates can be charged according to the number of executions of certificate validity check processing.
0132Although three embodiments have been described using examples which include checking for the validity of a public key certificate, the present invention can also be used for services in client and server systems that perform communications through various networks.
0133For example, for the service of browsing a database in a server, the present invention can be applied to limit a user's browsing by other users. Also, the present invention can be applied to service providing method that transfers the right to use server-provided online services from one user (service provider) to other users (service recipients) with limitations imposed by the service provider.
0134The present invention makes it possible for a service providing apparatus to appropriately perform information processing for service provision.
Contents4
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7966487B2 | Cited by | United States of America | Search report |
| US2013346744A1 | Cited by | United States of America | Pre-grant |
| US2013346743A1 | Cited by | United States of America | Pre-grant |
| US9755838B2 | Cited by | United States of America | Applicant |
| US9749139B2 | Cited by | United States of America | Applicant |
| US9426146B2 | Cited by | United States of America | Applicant |
| US8959337B2 | Cited by | United States of America | Search report |
| US7318155B2 | Cited by | United States of America | Search report |
| US2005255829A1 | Cited by | United States of America | Pre-grant |
| US7853791B1 | Cited by | United States of America | Search report |
| US2005193204A1 | Cited by | United States of America | Pre-grant |
| US2004111607A1 | Cited by | United States of America | Pre-grant |
| US9197631B2 | Cited by | United States of America | Search report |
| JP2000123095A | Cites | Japan | Applicant |
| JP2001005833A | Cites | Japan | Applicant |
| US2002013772A1 | Cites | United States of America | Search report |
| US2002035686A1 | Cites | United States of America | Search report |
| US2002053023A1 | Cites | United States of America | Search report |
| US5712914A | Cites | United States of America | Search report |
| US6564323B2 | Cites | United States of America | Applicant |
| US6754665B1 | Cites | United States of America | Applicant |
| JPH11149504A | Cites | Japan | Applicant |
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001346848 | Japan | – | |
| 2001346848 | Japan | A | |
| 2001346848 | Japan | A | |
| 2001346848 | – | – | – |
| JP20010346848 | – | – | – |
39 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| Expire Patent | |
| Maintenance Fee Reminder Mailed | |
| Correspondence Address Change | |
| Recordation of Patent Grant Mailed | |
| Patent Issue Date Used in PTA CalculationAllowed | |
| Issue Notification MailedAllowed | |
| Dispatch to FDC | |
| Application Is Considered Ready for Issue | |
| Issue Fee Payment Verified | |
| Issue Fee Payment Received | |
| Mail Notice of AllowanceAllowed | |
| Mail Examiner's Amendment | |
| Notice of Allowance Data Verification CompletedAllowed | |
| Case Docketed to Examiner in GAU | |
| Examiner's Amendment Communication | |
| Date Forwarded to Examiner | |
| Information Disclosure Statement considered | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Response after Non-Final Action | |
| Request for Extension of Time - Granted | |
| Correspondence Address Change | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| IFW TSS Processing by Tech Center Complete | |
| Case Docketed to Examiner in GAU | |
| Preliminary Amendment | |
| Application Dispatched from OIPE | |
| Application Is Now Complete | |
| IFW Scan & PACR Auto Security Review | |
| Information Disclosure Statement considered | |
| Request for Foreign Priority (Priority Papers May Be Included) | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Initial Exam Team nn |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.)FEPP | FEPP | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedurePAYER NUMBER DE-ASSIGNED (ORIGINAL EVENT CODE: RMPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedurePAYER NUMBER DE-ASSIGNED (ORIGINAL EVENT CODE: RMPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 07124294
- Publication, DOCDB
- 7124294
- Publication, EPODOC
- US7124294
- Application
- 10059332
- Application, DOCDB
- 5933202
- Application, EPODOC
- US20020059332
Titles
- English
- Electronic certificate system
Patent term adjustment
- A delay
- +962 daysthe office missed an examination deadline
- Applicant delay
- −48 days
- Net adjustment
- 914 days
Classification
- CPC, 1
- H04L9/3263
- IPC, 6
- H04L9 00
- G06F7 04
- G06Q50 00
- G06Q50 10
- G06Q50 26
- H04L9 32
- USPC, 3
- 713156000
- 713158000
- 726010000